Bugzilla – Bug 1187975
VUL-1: CVE-2021-22921: nodejs10,nodejs12,nodejs14,nodejs: Windows installer - Node Installer Local Privilege Escalation
Last modified: 2021-07-02 13:58:34 UTC
Windows installer - Node Installer Local Privilege Escalation (Medium) (CVE-2021-22921) Node.js is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking. You can read more about it in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22921 Impacts: All versions of the 16.x, 14.x, and 12.x releases lines https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/
not relevant for linux, closing